Back to homepage

Privacy

I’m Róisín Radford. I run Comms for Humans, a one-person communications consultancy in Utrecht, registered with the Dutch KvK under number 42143262. You can reach me at roisin@commsforhumans.com.

This page explains what I do with personal information. It’s written to be read, because a privacy policy nobody can follow isn’t really a privacy policy — and it would be a strange thing for a business called Comms for Humans to publish.

LAST UPDATED 24 AUGUST 2026

The short version

There are three ways your details might end up with me: you email me, I email you first, or you become a client. I don’t sell anything to anyone, I don’t track you, and if you’d rather I didn’t have your details, tell me and I’ll delete them.

This website

This site has a homepage and a privacy page, with links that open your email programme or direct you to my LinkedIn profile. There’s no contact form and no sign-up. 

My hosting provider, Lovable, runs basic visitor analytics so I can see whether people are clicking through – things like page views, referrer, and rough device/location data. It also sets the small cookies needed to serve the site and run those analytics. I don’t set cookies myself, and nothing you do here is recorded by me personally.

Like every website, it sits on a server, and that server keeps standard technical logs — including IP addresses — for security and reliability. Those are held by Lovable, and I don’t look at them.

If you email me

I’ll have whatever you put in your message: your name, your email address, and whatever you chose to tell me.

I use it to reply to you and to keep track of the conversation. That’s a legitimate interest — you wrote to me expecting an answer. If the conversation turns into work, it becomes part of getting that work done.

My email is hosted by Proton, who store it on my behalf. I chose them deliberately: their business model doesn’t involve reading it.

If I email you first

This is the section worth reading properly, because it’s the one where you didn’t choose to be in touch.

I approach organisations directly about communications work. If I’ve written to you out of the blue, here’s exactly what happened.

What I hold. Your name, your job title, your work email address, your employer, and whatever your organisation or your professional profile says about what you do. Nothing about your private life, and nothing you haven’t published in a professional capacity.

Where I got it. Your organisation’s own website, your public professional profile, press releases, news coverage, or a job advert. Sometimes I work out a work address from the format your organisation uses for its published staff addresses.

Why. I’m building a consultancy and I’d like to work with organisations that need what I do. That’s my legitimate interest under Article 6(1)(f) GDPR, and direct approaches of this kind are permitted under Article 11.7(3) of the Dutch Telecommunicatiewet for organisations, and fall outside the scope of PECR regulation 22 for UK companies.

How I keep that proportionate. I don’t send bulk email. Every message is researched and written individually, and I only write at all when I’ve found something specific and useful to say about your organisation — if I haven’t, I don’t send anything. I contact one person per organisation. I send one email and at most one follow-up; if you don’t reply, that’s the end of it. There are no tracking pixels, no read receipts, and no idea on my part whether you opened it.

Making it stop. Reply and say so. You don’t need a reason and you don’t need to be polite about it. I’ll stop immediately, and I’ll keep a note of your name and organisation for the sole purpose of never contacting you again. That’s the one thing I keep indefinitely, because deleting it would defeat the point.

If you become a client

I’ll hold what’s needed to do the work and to invoice you: contact details, correspondence, project material, and billing information. The basis is our contract, and for the invoicing part, my legal obligation to keep proper records.

I use Moneybird for invoicing and bookkeeping, so client billing details are stored there.

How long I keep things

Emails and enquiries that go nowhere
Reviewed at least yearly, deleted within 24 months
Research notes on organisations I looked at
Reviewed at least yearly, deleted within 24 months
"Don't contact me" records
Kept indefinitely, so I can honour them
Client records and invoices
As long as Dutch tax and commercial law require

Who else sees your information

Nobody, beyond the providers who host my email and website and the bookkeeping software I use to invoice. I don’t sell, share, rent or trade personal information, and I don’t use data brokers, contact-enrichment services or purchased lists.

Your rights

You can ask me to show you what I hold, correct it, delete it, or stop using it. You can object to my using your details at all.

Where the objection is about marketing or direct approaches, it’s absolute: no discussion, no balancing, no reason required. I stop.

Email me at roisin@commsforhumans.com and I’ll respond within a month, usually a great deal faster — there’s only one of me and it’s not a big inbox.

If you’re unhappy

Please tell me first, and I’ll try to put it right. If that doesn’t resolve it, you can complain to a data protection regulator: in the Netherlands, the Autoriteit Persoonsgegevens; in the UK, the Information Commissioner’s Office.

Changes

If I change how any of this works, I’ll update this page and change the date at the top.